A shocking 87% of retailers faced cyber incidents over the past 12 months, according to a new global study from Kaspersky, which gives insight into the risks and challenges the industry faces – and suggests ways to address them.

Retail is moving into an AI‑driven and personalised landscape where every digital touchpoint creates both convenience and risk. The new research by Kaspersky’s Internal Research Centre surveyed IT security specialists working in the retail sector across 18 countries and revealed key target areas, the most relevant threats, and the potential damage to business.

 

Cyber incidents and the goals behind the attacks

The retail sector – encompassing e-commerce, loyalty programmes, and personalised offerings – spans the entire transaction process from initial browsing to final payment, thereby accumulating massive volumes of personal data. With only 13% of survey respondents in the sector escaping cyber incidents over the past year, it is clear that this environment is highly vulnerable to cyberthreats and is highly appealing for cybercriminals.

As for the nature of the recently experienced incidents, phishing appeared to be the prevalent threat – reported by more than one-fifth of retailers (21%). Other social engineering-related attacks on retailers featured deepfakes (13%), invoice or payment fraud (13%), business email compromise (9%), and vishing (voice phishing) (8%). The top three most frequently experienced incidents in retailers also comprised cyber espionage (19%) and Web application exploits (18%).

During attacks, adversaries’ primary aims were stealing clients’ and employees’ personal data (34% and 28% respectively). Taken together, this diversity of threats shows that retailers are exposed not only to manipulation of employees and partners, but also to technically complex attacks against their online infrastructure.

 

Actual losses and measures taken

The most common actual results of the recent attacks on retailers included clients’ personal data theft (28%), financial loss (25%), and disruption of both business and operational processes (25%). In some cases, an attack could lead to more serious consequences that might threaten the existence of a business: irrecoverable data loss (19%) and irreversible damage to corporate assets or systems (16%).

Among the most popular protection measures taken after the most harmful incident organisations had experienced, were the implementation of Zero Trust or the Principle of Least Privilege for employees, partners and contractors (31%), strengthening cloud security controls (30%), and installation of monitoring IT security solutions (30%).

 

Internal incident risk factors

The survey also raised the question of internal factors which increase the likelihood of successful cyberattacks on retailers. According to the poll, human actions tend to be the primary concern with insufficient expertise among IT and security staff (27%) and a lack of security awareness (27%) topping the list. Technical shortcomings also had a strong impact: outdated software or hardware and the absence of centralised control over IT infrastructure are equally prevalent, at 23% each.

A lack of security awareness may be the reason behind risky workplace behaviours and associated losses. When asked about the most typical digital misbehaviour of their colleagues, more than third of respondents (34%) stated the use of personal devices for work‑related activities and the storage of corporate data. Almost equally widespread, in 33% of companies, employees practice irresponsible password habits – including weak or reused passwords and also connecting corporate devices to public Wi‑Fi networks without using a secure connection.

 

Budget changes and plans for future

Willing to enhance their IT security function, 82% of retailers increased their IT security budget this year. Unlike the general trend across other sectors, where organisations are largely planning to expand their internal IT teams, the retail industry is increasingly turning to third-party IT security providers. Almost half of these companies (41%) have allocated new funding to outsource specific IT security functions including employee education, MSSP, MDR, and the deployment of data protection technologies.

 

AI is set to play a key role in the future of retail

More companies are implementing AI tools in their infrastructure: 12% of retailers already have a working LLM-based tool, while 83% are currently in the discussion, design, or pilot phases. Although it speeds up operations, interestingly, 33% of retail companies claim they don’t see any risks in AI – which is significantly more than all industries’ indices (18%).

“Retail is a highly dynamic industry: business priorities, workloads, infrastructure requirements, and economic conditions change rapidly,” says Elizaveta Komarova, solution architect, Finance & Retail at Kaspersky. “To ensure that cybersecurity keeps pace with these changes, retailers choose to turn to external security service providers, gaining access to the required expertise and technologies without having to continuously expand their in-house teams.

“By outsourcing part of their cybersecurity functions, retailers effectively entrust an external partner with the resilience of their business processes and the financial risks associated with security incidents,” Komarova adds. “This makes it essential to have confidence in the provider’s experience, including a proven track record with retailers of different sizes, and to eliminate potential security blind spots through 24/7/365 protection.

“This is especially critical during peak periods, such as seasonal sales, periods of increased consumer demand, and holidays, when the cost of any disruption is particularly high and in-house teams may have limited availability”.